First published: Tue Feb 13 2007(Updated: )
The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server response of a specific length that causes a terminating null byte to be written outside of a buffer, which causes heap corruption.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2000 | =sp4 | |
Microsoft Internet Explorer | =5.01-sp4 | |
Microsoft Ie | =6.0-sp1 | |
Microsoft Windows 2003 Server | =gold | |
Microsoft Windows 2003 Server | =gold | |
Microsoft Windows 2003 Server | =gold | |
Microsoft Windows 2003 Server | =sp1 | |
Microsoft Windows 2003 Server | =sp1 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Internet Explorer | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.